REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'thpless'
b'springboot actuator is leaking internals at '
14 Sep 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'0x45'
b'Directory Traversal at '
14 Sep 2022
b'Meredith'
disclosed a bug submitted by
b'error201'
b"Shop - Reflected XSS With Clickjacking Leads to Steal User's Cookie In Two Domain"
14 Sep 2022
b'Dropbox'
disclosed a bug submitted by
b'fransrosen'
b'Abuse cookie-modification, toast HTML and expired domain in CSP-form-action replacing login-page at www.dropbox.com/login to submit creds externally'
14 Sep 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'fdeleite'
b'Reflected XSS []'
14 Sep 2022
b'TikTok'
disclosed a bug submitted by
b'f_m'
b'CSRF in Changing User Verification Email'
13 Sep 2022
b'Glassdoor'
disclosed a bug submitted by
b'nokline'
b'Web Cache Poisoning leads to XSS and DoS'
13 Sep 2022
b'Glassdoor'
disclosed a bug submitted by
b'nokline'
b'XSS in http://www.glassdoor.com/Search/results.htm via Parameter Pollution'
13 Sep 2022
b'Hyperledger'
disclosed a bug submitted by
b'cre8'
b'DOS validator nodes of blockchain to block external connections'
13 Sep 2022
b'GitLab'
disclosed a bug submitted by
b'patronum-m'
b'No Restriction on password'
13 Sep 2022
b'GitLab'
disclosed a bug submitted by
b'afewgoats'
b'ReDoS in net/http affects webhooks: Sidekiq job stuck at 100% CPU for a year'
13 Sep 2022
b'GitLab'
disclosed a bug submitted by
b'vakzz'
b'RCE via the DecompressedArchiveSizeValidator and Project BulkImports (behind feature flag)'
13 Sep 2022
b'Monero'
disclosed a bug submitted by
b'm31007'
b'monerod JSON RPC server remote DoS'
12 Sep 2022
b'Sony'
disclosed a bug submitted by
b'0x2374'
b'Response Manipulation leads to Admin Panel Login Bypass at https://admin.indevice.sonymobile.com/'
12 Sep 2022
b'Cloudflare Public Bug Bounty'
disclosed a bug submitted by
b'imtheking'
b'Signup with any Email and Enable 2-FA without verifying Email'
12 Sep 2022
b'Nextcloud'
disclosed a bug submitted by
b'luchua'
b'Access to arbitrary file of the Nextcloud Android app from within the Nextcloud Android app'
11 Sep 2022
b'Internet Bug Bounty'
disclosed a bug submitted by
b'gquadros_'
b'CVE-2022-21831: Possible code injection vulnerability in Rails / Active Storage'
10 Sep 2022
b'IBM'
disclosed a bug submitted by
b'zere'
b'Cleartext storage of sensitive information at https://staging.status.ai-apps-comms.ibm.com/env can lead to account takeover of several IBM employees'
09 Sep 2022
b'MTN Group'
disclosed a bug submitted by
b'aliyugombe'
b'String length restriction byepass at https://callerfeel.mtnonline.com/profile/feedback.html'
07 Sep 2022
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b's1m0x1'
b'Reflected Xss in []'
06 Sep 2022
1
...
113
114
115
116
117
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM